Alerts This Week
Warning Icon 1 664
Alerts This Week
Warning Icon 1 664

openSUSE 2026 Critical osslsigncode Memory Corruption DoS 2026-0115-1

opensuse
Calendar Grey April 3, 2026
Dist Opensuse Esm H88
Critical security update for openSUSE's osslsigncode fixes multiple memory issues and buffer overflow risks effectively.
An update that fixes one vulnerability is now available.

Description

This update for osslsigncode fixes the following issues:

- Update to 2.13 (boo#1260680, CVE-2025-70888):

* fixed integer overflows when processing APPX compressed data streams

* fixed double-free vulnerabilities in APPX file processing

* fixed multiple memory corruption issues in PE page hash computation

- Changes from 2.12:

* fixed a buffer overflow while extracting message digests

- Changes from 2.11:

* added keyUsage validation for signer certificate

* added printing CRL details during signature verification

* implemented a workaround for CRL servers returning the HTTP

Content-Type header other than application/pkix-crl

* fixed HTTP keep-alive handling

* fixed macOS compiler and linker flags

* fixed undefined BIO_get_fp() behavior with BIO_FLAGS_UPLINK_INTERNAL

- update to 2.10:

* added JavaScript signing

* added PKCS#11 provider support (requires OpenSSL 3.0+)

* added support for providers...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Backports SLE-15-SP6:

zypper in -t patch openSUSE-2026-115=1

Package List

- openSUSE Backports SLE-15-SP6 (aarch64 i586 ppc64le s390x x86_64):

osslsigncode-2.13-bp156.2.3.1

References

https://www.suse.com/security/cve/CVE-2025-70888.html

https://bugzilla.suse.com/1260680

Severity
critical
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2026:0115-1
Rating: critical
Affected Products: openSUSE Backports SLE-15-SP6

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here